IBM Support

PM56143: ADMIN CONSOLE USERS/GROUPS MAPPING POINTS TO THE INCORRECT USER REGISTRY.

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • Running zWAS800, it was observed that...
    When attempted to modify an existing application (EAR) in admin
    console using Security>Role to user/group mapping,
    Admin console appears to fetch users/groups from wrong user
    registry.
    
    Instead of fetching it from the configured user registry in the
    Security Domain where the application is installed, it seems to
    fetch the users/groups from the registry defined at the global
    security settings.
    
    
    This problem seems to surface only when doing administration via
    admin console. At runtime the server/cluster where the
    application is installed, seems to validate authorization to
    the correct/intended user registry.
    

Local fix

  • Manually edit the Security.xml file to define the 'realm' under
    the <userRegistries>
    
    <userRegistries xmi:type="security:LocalOSUserRegistry"
    xmi:id="LocalOSUserRegistry" serverId="" serverPassword="{xor}"
    realm="" ignoreCase="false" useRegistryServerId="false"
    primaryAdminId="" useRegistryRealm="true"/>
    
    In this particualr reported case, we changed
    realm="" to realm="<value>" on the zWAS800 cell.
    

Problem summary

  • ****************************************************************
    * USERS AFFECTED:  All users of IBM WebSphere Application      *
    *                  Server V8.0 for z/OS who use the Local OS   *
    *                  user registry for administration and        *
    *                  define a separate user registry             *
    *                  for applications.                           *
    ****************************************************************
    * PROBLEM DESCRIPTION: The Administrative Console gets users   *
    *                      or groups for role mapping from the     *
    *                      Local OS user registry.                 *
    ****************************************************************
    * RECOMMENDATION:                                              *
    ****************************************************************
    When using the Adminstrative Console to map security roles to
    users or groups for an application, the Local OS user registry
    is incorrectly used when a separate user registry has been
    defined for the application.
    

Problem conclusion

  • The code has been corrected to properly detect all user
    registries.  By default it will query the proper user registry
    for users and/or groups.  A drop down menu is diplayed such
    that the user can optionally select a realm association with a
    different user registry, if necessary.
    
    APAR PM56143 is currently targeted for inclusion in
    Service Level (Fix Pack) 8.0.0.4 of WebSphere Application
    Server V8.0.
    
    Please refer to the Recommended Updates page for delivery
    information:
    http://www.ibm.com/support/docview.wss?rs=180&uid=swg27004980
    
    In addition, please refer to URL:
    http://www.ibm.com/support/docview.wss?rs=404&uid=swg27006970
    for Fix Pack PTF information.
    

Temporary fix

Comments

APAR Information

  • APAR number

    PM56143

  • Reported component name

    WEBSPHERE FOR Z

  • Reported component ID

    5655I3500

  • Reported release

    800

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt

  • Submitted date

    2012-01-17

  • Closed date

    2012-02-24

  • Last modified date

    2012-08-09

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    WEBSPHERE FOR Z

  • Fixed component ID

    5655I3500

Applicable component levels

  • R800 PSY

       UP

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SS7K4U","label":"WebSphere Application Server for z\/OS"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"800","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
28 October 2021